CVE-2026-5757 Details
Description
Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive data exposure, further compromise, and stealthy persistence.
A vulnerability allowing unauthenticated remote information disclosure has been identified in Ollama's model quantization engine. This issue arises from an out-of-bounds heap read/write vulnerability, which allows an attacker to read and exfiltrate the server's heap memory. The vulnerability is present in Ollama, an open-source tool for running large language models locally on various operating systems, including macOS, Windows, and Linux. The issue is caused by the quantization engine's lack of proper bounds checking on tensor metadata from user-supplied GPT-Generated Unified Format (GGUF) files. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, further system compromise, and stealthy persistence.
As of now, no patch is available for this vulnerability. However, access to the model upload functionality should be restricted or disabled, especially in environments exposed to untrusted users or networks. If model uploads are necessary, only accept models from trusted sources and apply appropriate validation controls.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/518910 | CVE | Third Party AdvisoryVDB Entry |
| https://kb.cert.org/vuls/id/518910 | [email protected] | Third Party AdvisoryVDB Entry |
| https://ollama.com | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ollama ollama | <= 0.13.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |
| Jun 26, 2026 | CVE Modified | CVE |